Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side validation to confirm that the requesting user is authorized to access the requested object or dataset. This vulnerability can be exploited in two ways: Direct ID manipulation and IDOR, by changing an ID parameter (e.g., user_id, project_id) in the request, an attacker can access the object and data belonging to another user; and filter Omission, by omitting the filtering parameter entirely, an attacker can cause the endpoint to return an entire unfiltered dataset of all stored records for all users. This flaw leads to the unauthorized exposure of sensitive personal and organizational information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Primakon Pi Portal 安全漏洞
Vulnerability Description
Primakon Pi Portal是克罗地亚Primakon公司的一个项目、合同管理平台。 Primakon Pi Portal 1.0.18版本存在安全漏洞,该漏洞源于API端点验证不足,可能导致未经授权的数据访问。
CVSS Information
N/A
Vulnerability Type
N/A